C.W.K.
Stream
Quiz · 6 questions

🛡️ Auth & Security — Wire-Level, Not Hand-Waved

Bearer, API keys, JWT, OAuth2 with PKCE, CORS, rate limiting

Level 0HTTP Newbie
0 XP0/46 lessons0/12 achievements
0/120 XP to next level120 XP to go0% complete

Quiz

01What's the actual difference between HTTP Basic and Bearer auth on the wire?
02Why is a static long-lived API key worse than a short-lived bearer token, from a security standpoint?
03What are the three parts of a standard JWT, and what does the signature actually prove?
04Why is OAuth2 with PKCE the canonical flow in 2026, even for native and single-page apps?
05Whose decision is it whether your browser allows a cross-origin request?
06Your client receives 429 Too Many Requests with Retry-After: 60. What's the correct behavior?
Spotted a bug or have feedback on this page?Report an Issue

Comments 0

🔔 Reply notifications (sign in)
Sign inPlease sign in to comment.

No comments yet — be the first.